Releases: Mo3he/Axis_Cam_OpenVPN
Release list
OpenVPN VPN 3.11.7
OpenVPN VPN 3.11.7
Packages OpenVPN3 Core 3.11.7.
Upstream changes
https://github.com/OpenVPN/openvpn3/tree/release/3.11.7
Changes
- Update to upstream 3.11.7.
Packages
Install the signed_*.eap matching your device architecture.
Full changelog: v0.1.4...v3.11.7
OpenVPN VPN 0.1.4
Upgrade from 0.1.2 or 0.1.3 right away. On those versions the tunnel connects and reports connected, but carries no traffic at all.
Fix: the userspace data plane never started
0.1.2 renamed the app from OpenVPN to OpenVPN_VPN, but the tun probe still launched the netstack sidecar from the old /usr/local/packages/OpenVPN/lib path. The execl failed on every connect, so the data plane never came up:
- the transparent port forwarders never listened
- the inbound SOCKS5 proxy on the VPN address never listened
- the outbound HTTP and SOCKS5 proxies never listened
- the client logged
TUN write exception: Connection refusedand reconnected in a loop
0.1.0 and 0.1.1 were not affected.
The failure was invisible because the execl error path exited silently and the probe and sidecar logged under an OpenVPN syslog tag that the app log never shows. Both are fixed, so a future failure will be logged where you can see it.
Configurable forwarded ports
Also included, from 0.1.3: the directly forwarded ports are configurable instead of fixed at 80, 443 and 554. Add port 22 to reach SSH over the VPN.
80,443,554,22
Set it under Forwarded ports in Settings, or via the parameter API:
curl --digest -u <username>:<password> \
--data "action=update&root.OpenVPN_VPN.ForwardPorts=80,443,554,22" \
"http://<device-ip>/axis-cgi/param.cgi"Up to 16 ports. Duplicates, out-of-range values and stray whitespace are ignored, and an empty value restores the default.
Security: every listed port is reachable from the VPN. Control access with your server's client configuration and firewall rules, and keep the camera behind its normal authentication.
Verified
Tested on an AXIS D6310 (AXIS OS 13) against a real OpenVPN server: SSH and HTTPS both work over the tunnel on the configured ports, an unconfigured port stays closed, and the client no longer restart-loops.
Packages
| Package | For |
|---|---|
signed_OpenVPN_VPN_0_1_4_aarch64.eap |
Most cameras. AXIS OS 10.x - 13, 64-bit |
signed_OpenVPN_VPN_0_1_4_armv7hf.eap |
AXIS OS 10.x - 13, 32-bit |
Both are signed with the Axis ACAP signing service and install normally on AXIS OS 12.10 and later. Upgrading in place keeps your existing settings.
OpenVPN VPN 0.1.3
Do not use this release. The userspace data plane never starts, so the tunnel reports connected while carrying no traffic: no port forwarding, no SOCKS5, no outbound proxies. Fixed in v0.1.4.
Configurable forwarded ports
The directly forwarded ports are now configurable instead of fixed at 80, 443, and 554. Add port 22 to reach SSH over the VPN, or any other camera service you need for remote diagnostics.
Set them in the app's settings page under Forwarded ports, as a comma-separated list:
80,443,554,22
Or through the parameter API:
curl --digest -u <username>:<password> \
--data "action=update&root.OpenVPN_VPN.ForwardPorts=80,443,554,22" \
"http://<device-ip>/axis-cgi/param.cgi"Up to 16 ports are accepted. Duplicates, out-of-range values and stray whitespace are ignored, and leaving the field empty restores the 80, 443, 554 default.
Security: every listed port is reachable from the VPN. Control access with your server's client configuration and firewall rules, and keep the camera behind its normal authentication.
Packages
| Package | For |
|---|---|
signed_OpenVPN_VPN_0_1_3_aarch64.eap |
Most cameras. AXIS OS 10.x - 13, 64-bit |
signed_OpenVPN_VPN_0_1_3_armv7hf.eap |
AXIS OS 10.x - 13, 32-bit |
Both packages are signed with the Axis ACAP signing service and install normally on AXIS OS 12.10 and later.
Upgrading in place keeps your existing settings. A full uninstall and reinstall resets them to defaults.
OpenVPN VPN 0.1.2
Do not use this release. The userspace data plane never starts, so the tunnel reports connected while carrying no traffic: no port forwarding, no SOCKS5, no outbound proxies. Fixed in v0.1.4.
Fix broken app name and save settings without param.cgi
Two fixes in this release:
- The app package name used by the bridge and web UI did not match the manifest
appName(OpenVPN_VPN). As a result the client binary was launched from the
wrong path, so the tunnel never started, and settings were read from the wrong
parameter namespace. All internal references now useOpenVPN_VPN. - Settings (username, password, proxy ports) can now be saved on Axis devices
that do not expose/axis-cgi/param.cgi, such as recorder/NVR products
(e.g. S3008) and access-control controllers (e.g. A1610, A1710, A1810). The
app serves/local/OpenVPN_VPN/api/settings; the web UI usesparam.cgiwhen
available and falls back to this endpoint otherwise, writing through the ACAP
parameter store.
Packages are signed with the Axis ACAP signing service and install on
AXIS OS 12.10 and later.
OpenVPN VPN 0.1.1 (Signed)
These .eap packages are signed with the Axis ACAP signing service and install
normally on AXIS OS 12.10 and later.
Upgrading from an earlier version
Because the signing vendor changed, installing over a previously installed
unsigned version can fail with "Couldn't install: app". The device log
shows:
Vendor ID in manifest does not match the vendor ID of the previous version
To upgrade: back up your app configuration, uninstall the existing app,
then install this signed version.
OpenVPN Client v0.1.1
AXIS OS 13 readiness release.
Rebuilt on the ACAP Native SDK 12.10.0 (Ubuntu 24.04) with the changes needed to survive the AXIS OS 13 upgrade, while keeping the AXIS OS 11 floor working.
Changes:
- 64-bit time (Y2038): recompiled against SDK 12.10.0.
- Manifest schema v2 (2.0.0): declares compatibleOsVersions (max 13) and a vendorId.
- Non-executable stack on all shipped binaries (GNU_STACK RW).
- Bundles a statically linked OpenSSL 3.5 in tun_probe so it no longer depends on the device's OpenSSL version, and forwards the C23 _isoc23* symbols locally, keeping the max glibc requirement at 2.34.
Tested: live-validated on AXIS OS 11.11.212 (P3265-LVE) and 12.10.73 (Q3538-LVE) — full VPN connect on 12.10.
Install the .eap matching your camera's architecture (aarch64 or armv7hf).
OpenVPN Client v0.1.0
First release of the OpenVPN Client ACAP for Axis cameras.
Runs an OpenVPN client directly on the camera, entirely in userspace, with no
root and no kernel TUN device. Verified on Axis OS 12.
Features:
- Non-root: runs as the unprivileged
sdkACAP user - OpenVPN3 core terminates the tunnel in userspace (socketpair instead of /dev/net/tun)
- gVisor netstack + proxy layer: transparent forwarders for 80/443/554,
inbound SOCKS5, outbound HTTP CONNECT and SOCKS5 - Reach the camera from your VPN, and route camera traffic out through it
- Web UI to upload the .ovpn profile, set credentials and proxy ports, and view logs
Install the .eap matching your camera architecture (aarch64 or armv7hf) via
Apps then Add app.
Licensed under AGPL-3.0. See THIRD_PARTY_NOTICES.md for bundled components.